← 返回 Skills 市场
Pipeworx Analyst
作者
Bruce Gutman
· GitHub ↗
· v1.0.0
· MIT-0
80
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install pipeworx-analyst
功能描述
Access 252 data sources via one gateway to query trade, finance, pharma, housing, and government contracts using natural language questions.
安全使用建议
Do not install or use this skill unless you trust the external gateway and have clear answers to: (1) Who operates gateway.pipeworx.io (company/owner/public repo)? (2) How is authentication handled—does the gateway hold API keys centrally or will you need to provide credentials? (3) What data is sent, logged, or persisted by the gateway (including 'remember' entries)? retention and deletion policies? (4) Is traffic encrypted and who can access logs? Ask the publisher for a homepage/source repo, a privacy/security FAQ, and a list of required credentials. Test with non-sensitive queries first. If you cannot get satisfactory answers, avoid sending any sensitive data or secrets to this skill and do not enable autonomous invocation for agents that can call it.
功能分析
Type: OpenClaw Skill
Name: pipeworx-analyst
Version: 1.0.0
The skill bundle serves as a configuration and instruction set for an MCP (Model Context Protocol) gateway connecting to `gateway.pipeworx.io`. The instructions in SKILL.md and the configuration in _meta.json are consistent with the stated purpose of providing a data analysis interface for various public and commercial data sources (trade, finance, pharma). No evidence of malicious intent, data exfiltration, or harmful prompt injection was found.
能力评估
Purpose & Capability
The SKILL.md consistently points the agent at an external gateway (https://gateway.pipeworx.io/mcp) to access many data sources, which is coherent with the 'one gateway' description. However, several listed backends (e.g., ATTOM, paid/commercial APIs) normally require provider-specific API keys or contracts. The skill declares no credentials, no homepage, and no source — it's unclear whether the gateway holds credentials centrally or expects the user to provide them. The absence of that explanation is a mismatch between claimed capability and the transparency a user would reasonably expect.
Instruction Scope
The runtime instructions tell the agent to call remote functions (ask_pipeworx, discover_tools, remember, recall) against an external URL. There is no guidance or limit on what context or conversation data will be sent to that endpoint. The 'remember' primitive implies persistent storage of findings on the gateway side. Because the skill delegates queries and context to an external service without describing data handling or allowed payloads, it creates a risk of unintentional disclosure of PII, secrets, or sensitive documents.
Install Mechanism
This is instruction-only with no install spec and no code files, so nothing is written to disk by the skill itself. That minimizes local install risk. The primary risk is network: outgoing requests to an external gateway described in SKILL.md.
Credentials
The skill declares no required environment variables or primary credential, yet it claims access to many third-party sources that often require their own API keys. Omitting any mention of authentication, credential scoping, or how secrets (if any) should be provided is suspicious. Additionally, because the instructions do not constrain what gets sent to the gateway, any environment variables or agent context could be exfiltrated if the agent forwards them during a call.
Persistence & Privilege
The skill is not forced always-on (always: false), but autonomous invocation is allowed (the platform default). Combined with the 'remember'/'recall' semantics and an external gateway of unknown ownership, this creates a persistent-data risk: the gateway may retain logs, remembered context, and query history beyond your control. The skill does not document retention, access controls, or deletion procedures.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install pipeworx-analyst - 安装完成后,直接呼叫该 Skill 的名称或使用
/pipeworx-analyst触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release
元数据
常见问题
Pipeworx Analyst 是什么?
Access 252 data sources via one gateway to query trade, finance, pharma, housing, and government contracts using natural language questions. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 80 次。
如何安装 Pipeworx Analyst?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install pipeworx-analyst」即可一键安装,无需额外配置。
Pipeworx Analyst 是免费的吗?
是的,Pipeworx Analyst 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Pipeworx Analyst 支持哪些平台?
Pipeworx Analyst 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Pipeworx Analyst?
由 Bruce Gutman(@brucegutman)开发并维护,当前版本 v1.0.0。
推荐 Skills